HomeDefectsLIN1022-36355
Fixed

LIN1022-36355 : Security Advisory - linux - CVE-2026-89839

Created: Oct 7, 2026    Updated: Oct 8, 2026
Resolved Date: Oct 7, 2026
Found In Version: 10.22.33.2
Fix Version: 10.22.33.11
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()  f2fs_xattr_advise_set() calls inode_owner_or_capable() with &nop_mnt_idmap before allowing the system.advise xattr to be set, instead of the idmap that the VFS passes to the ->set() handler.  f2fs supports idmapped mounts, so on such a mount this checks the caller's fsuid against the unmapped on-disk owner rather than the mapped owner: the actual owner can be wrongly denied with -EPERM and an unrelated caller wrongly allowed.  Pass the handler's idmap instead.